Drop-in audit SDK for MAS-licensed lenders. Every LLM decision hash-chained, tamper-evident, and Bitcoin-anchored. Three lines of code to integrate.
The November 2025 AI Risk Management Guidelines made audit trails a current obligation — not a future one. Most lenders' infrastructure was not built for this.
OpenAI, Anthropic, and AWS Bedrock don't store your prompts permanently. When MAS asks for a decision audit, the evidence is already gone.
30-day default expiryEven if you have logs in a database, there's no cryptographic proof they weren't modified after the fact. A log file is not tamper-proof evidence.
Zero integrity guaranteesUnder the IAC regime, the Chief Compliance Officer is personally liable if AI credit decisions can't be explained, reproduced, or proven to a regulator.
Individual Accountability & ConductFEAT Principles are active. The 2025 AI Risk Management Guidelines are binding for all MAS-licensed FIs. This is not a future requirement.
Effective November 2025Drop into your existing LLM pipeline. Zero changes to your credit logic. Zero impact on your p99 latency.
Full prompt, model response, model name, version, token counts, and latency — captured automatically without changing your code logic.
SHA-256 linked blocks. Each record includes the hash of the previous record. Any modification or deletion breaks the chain. Mathematically unalterable.
Daily Merkle batch anchored to the Bitcoin blockchain via OpenTimestamps. Cryptographic proof that your records existed before any future dispute.
Single API call generates a verified PDF: chain certificate, OTS Bitcoin proofs, full decision log. Ready to hand to a regulator in under 60 seconds.
OpenAI / Anthropic / Bedrock inside your credit pipeline
3-line SDKCaptures call, HMAC-signs, hashes with prev block, async POST
Non-blockingValidates, appends chain, encrypts PII at rest (AES-256)
AWS ap-southeast-1Daily Merkle batch to Bitcoin via OpenTimestamps
Immutable timestampChain cert + OTS proofs + full decision log PDF
Audit-readyEvery Veritrail feature maps directly to a MAS obligation. No interpretation required when the regulator asks.
| MAS Requirement | Veritrail Feature |
|---|---|
| FFairness — decisions must be explainable | ✓ Full LLM replay: exact prompt + model response stored immutably |
| EEthics — align with documented ethical standards | ✓ Policy version + outcome reason per decision, append-only |
| AAccountability — complete audit trail required | ✓ SHA-256 hash chain, monotonic sequence, access log |
| TTransparency — model versioning must be logged | ✓ model_id, model_version, policy_version per decision |
| IAC — personal CCO liability for AI decisions | ✓ Cryptographic proof chain + OTS Bitcoin timestamping |
| 2025 AI Risk Management Guidelines | ✓ One-click Inspection Package PDF — chain cert + OTS proofs |
MAS-licensed entities are required to conduct vendor due diligence before onboarding third-party AI infrastructure. Veritrail is designed to pass it: TLS-encrypted API, Singapore data residency, append-only storage, and full audit documentation available on request.
OpenAI retains request data for 30 days by default. AWS Bedrock logs require manual configuration. If MAS requests a 12-month audit of AI credit decisions made today, most lenders cannot produce it. Veritrail stores everything, permanently, from the moment you integrate.
Not a concept or prototype. Deployed and operational on AWS ap-southeast-1.
Running on ECS Fargate, ap-southeast-1. Health checks passing. 7-day uptime, zero incidents.
All data in transit encrypted via TLS 1.2+. All data at rest encrypted with AES-256-GCM. No exceptions.
All data stored in AWS ap-southeast-1 (Singapore). No cross-border data transfer. PDPA-compliant by architecture.
Append-only linked blocks. Any modification breaks the cryptographic chain. Independently verifiable.
Daily Merkle root anchored to the Bitcoin blockchain via OpenTimestamps. External, immutable timestamp proof.
GitHub Actions → ECR → ECS. Full test suite on every push. Automated deployment with zero-downtime rollout.
Design partners shape the product roadmap. Early access pricing is locked in for the life of the account.
20-minute demo. I'll show you a live AI decision being logged, hash-chained, replayed, and packaged for a regulator — against your actual use case.
Book a demo